HCL BigFix is pleased to announce several key enhancements to BigFix Remote Control.
Web Based Controller
This release introduces the Web Controller, allowing operators to start active or monitor Broker Sessions directly from a browser via the Remote Control Lite Web Portal (LWP). This eliminates the need to install the standalone RC Controller application. Please note that this initial version has limited functionality compared to the standalone application. We plan to extend this new component by adding new features over time.
Key limitations include:
- Only Monitor and Active Session modes are available.
- Only Broker Session types with Connection Codes are supported (Managed and Unattended Sessions type are not available).
- Supported browsers: Edge and Chrome.
- File Transfer and Chat are not currently supported
- Session re-connection in case of an unexpected connection drop is not currently supported
- Maximum number of concurrent Web Controller sessions is limited to 10 for each Broker
- Quick Text Input is not currently supported
- Privacy Mode is not currently supported
- Joining sessions or collaborations is not currently supported
- Multi screen selection is not currently supported
- Smart Card selection is not allowed
RestAPI for Integration with Remote Control
New REST APIs enable integration with external products. These APIs allow users to check available Session Modes for specific computers, initiate Web Controller sessions, and retrieve session recordings.
Single Sign-On (SSO) for Lite Web Portal (LWP)
SSO is now available for the Lite Web Portal, allowing users to log in seamlessly without manually entering credentials each time.
New application server and Java runtime
IBM WAS Liberty has been replaced with Open Liberty version 25, and the Java runtime has been upgraded to IBM Java Semeru version 25.
The default keystore now is PKCS#12 (.p12).
The Server now uses FFmpeg to export recordings so JMF and XVID are no longer needed.
Usage Notes and Limitations:
- The RC Server now only supports 64-bit architectures; 32-bit support has been discontinued.
- The iKeyman tool used to handle keystores has been replaced by the Java Semeru keytool utility.
- Lack of connection with Oracle if FIPS is enabled
- JDBC drivers should be updated to support Java 25
- JKS Keystores are not supported if FIPS is enabled
New Java runtime and FIPS 140-3 support for the Controller
The Java runtime for the Controller application has been upgraded to IBM Java Semeru version 25.
Now the Controller supports the FIPS 140-3 module.
Usage Notes and Limitations:
- The RC Controller now only supports 64-bit architectures; 32-bit support has been discontinued.
Azure SQL Managed Instance
The Remote Control Server database can now be hosted using the Azure SQL Managed Instance cloud service.
**Fixed vulnerabilities**
This release addresses the following vulnerabilities:
- CVE-2026-33870 and CVE-2026-33871: affecting the Remote Control Server, which could allow request smuggling or Denial of Service (DoS) attacks.
Affected component: Remote Control Server.
Affected version: Remote Control version 10.1.0 FP4 and earlier.
**Resolved Defect Articles:**
KB0129071: Entra ID configuration utility allows to connect with plaintext secret and the Secret Encrypted flag enabled
KB0128078: Entra ID users membership sync is not working
KB0129807: Unable to export the recording
KB0127880: DOC - Remote Control AV Exclusion for Linux / Mac
KB0127810: DOC - Remote Control SSL not working
KB0127558: DOC - Add that File Transfer doesn't keep file metadata
**Published site version:**
Remote Control, site version 84 (Build Number 10.1.0.0548)
With kind regards,
The BigFix Remote Control Team